VYPR

Experience Manager

by Adobe Inc.

CVEs (1,168)

  • CVE-2023-48599MedDec 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within…

  • CVE-2022-42351MedDec 16, 2022
    risk 0.28cvss 4.3epss 0.01

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to disclose low level confidentiality information.…

  • CVE-2024-41849MedAug 23, 2024
    risk 0.27cvss 4.1epss 0.00

    Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged attacker could leverage this vulnerability to slightly affect the integrity of the page. Exploitation…

  • CVE-2021-28626LowAug 24, 2021
    risk 0.24cvss 3.7epss 0.01

    Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by an Improper Authorization vulnerability allowing users to create nodes under a location. An unauthenticated attacker could leverage this vulnerability to cause an application…

  • CVE-2026-48289LowJun 9, 2026
    risk 0.23cvss 3.5epss 0.00

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain…

  • CVE-2026-48288LowJun 9, 2026
    risk 0.23cvss 3.5epss 0.00

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain…

  • CVE-2025-47096LowJun 10, 2025
    risk 0.23cvss 3.5epss 0.00

    Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, allowing a low impact to the integrity of the component. Exploitation of this issue requires user interaction in that a…

  • CVE-2024-52831LowDec 10, 2024
    risk 0.23cvss 3.5epss 0.01

    Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the…

  • CVE-2024-43755LowDec 10, 2024
    risk 0.23cvss 3.5epss 0.01

    Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the…

  • CVE-2024-41839LowJul 23, 2024
    risk 0.23cvss 3.5epss 0.00

    Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the…

  • CVE-2024-36226LowJun 13, 2024
    risk 0.23cvss 3.5epss 0.01

    Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the…

  • CVE-2024-26127LowJun 13, 2024
    risk 0.23cvss 3.5epss 0.01

    Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the…

  • CVE-2024-26126LowJun 13, 2024
    risk 0.23cvss 3.5epss 0.01

    Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the…

  • CVE-2023-48608LowDec 15, 2023
    risk 0.23cvss 3.5epss 0.01

    Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation vulnerability. A low-privileged attacker could leverage this vulnerability to achieve a low-integrity impact within the application. Exploitation of this issue requires user…

  • CVE-2022-44488LowDec 19, 2022
    risk 0.23cvss 3.5epss 0.00

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2026-48359CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.02

    Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive…

  • CVE-2026-48355MedJul 14, 2026
    risk 0.00cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the…

  • CVE-2026-48310HigJul 14, 2026
    risk 0.00cvss 8.6epss 0.01

    Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside…

  • CVE-2026-48263MedJul 14, 2026
    risk 0.00cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the…

  • CVE-2026-48262MedJul 14, 2026
    risk 0.00cvss 5.4epss 0.00

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires…

Page 58 of 59